ARCHIVED READING · PERMANENT RECORD
WEEK OF SEPTEMBER 21, 2026
73/ 100HIGH PRESSURE
Passkey-themed social engineering graduates from research to active intrusions, while exploitation holds at its peak behind a max-severity Cisco ISE zero-day.
↑ 1 POINT SINCE LAST WEEK2026-W39ISSUED 2026-09-21 · 14:00 UTCMETHODOLOGY V1.0
SIGNALS
ACTIVE EXPLOITATION→
STEADY
Held at last week's peak: a CVSS 10.0 Cisco ISE zero-day and a Secure Email Gateway root-execution flaw join eight current KEV additions; the Chrome-Windows zero-day chain is now attributed in ongoing intrusions.
RATIONALE & SOURCE TYPES
Eight current-year KEV additions: Cisco Identity Services Engine (zero-day authentication bypass, CVSS 10.0, exploited in active attacks against the identity/NAC layer itself), Cisco Secure Email Gateway (root command execution), ConnectWise ScreenConnect (remote management again), two more JFrog Artifactory flaws, GitLab, Google Pixel modem (limited targeted exploitation), and Acronis Backup. China-linked actors are deploying GRIMWEDGE via last week's Chrome-Windows zero-day chain, and Red Heron compromised thirteen organizations via the Gitea RCE. Intense, but comparable to last week's record rather than above it — held. Confidence is high.
CISA KEVVENDOR ADVISORYINCIDENT REPORTING
IDENTITY & HUMAN ATTACK PRESSURE↑
RISING
The passkey watch item converts: Microsoft confirms passkey-themed social engineering in active cloud intrusions — helpdesk-impersonation lures driving AitM and device-code flows against the control defenders migrated to.
RATIONALE & SOURCE TYPES
Microsoft Security Research reports active intrusions since May in which passkey-update pretexts — delivered by fake IT-helpdesk calls and SMS to personal phones — steer victims into adversary-in-the-middle or device-code authentication flows, followed by attacker-added authentication methods, bulk Graph and SharePoint access, and mailbox collection (activity attributed to Storm-3121, Storm-3032, and others). Flagged as research-only in W34; now observed at scale, with vendor research and independent reporting supplying two source classes. The N0va phishing kit, a Twitch extension leaking 31,000 OAuth tokens, and KREMLIN browser-hijack malware round out the week. Confidence is medium: campaign scope is still being mapped.
VENDOR RESEARCHINCIDENT REPORTING
INTRUSION / RANSOMWARE TEMPO→
STEADY
A quieter disclosure week: one material-incident follow-up filing and a large consumer-platform breach; tempo holds at the recent raised level.
RATIONALE & SOURCE TYPES
Nutex Health filed a materiality-assessment update to its earlier Item 1.05 (a follow-on, not a new incident); Gyazo disclosed a breach spanning 23.6 million user records; Spain's data authority logged its first report of an AI-powered breach. Activity consistent with — not exceeding — recent weeks. Confidence is medium: disclosure lag limits week-level precision.
PUBLIC DISCLOSUREINCIDENT REPORTING
THREE MOVES THIS WEEK
01Patch the Cisco ISE zero-day now and audit ISE admin-API activity — a CVSS 10.0 bypass of the identity layer is compromise-assumed territory.
02Tell staff plainly: no real helpdesk asks you to update passkeys or MFA via a link or SMS — route every such request to a verified internal channel.
03Patch ScreenConnect and Artifactory again and review their access logs — remote-management and artifact infrastructure keep recurring in KEV.
WHY WE BELIEVED THIS
RECEIPT LOG · WEEK 3910 RECEIPTS
REVISION HISTORY
2026-09-21 · 14:00 UTCOriginal publication.
← FULL ARCHIVE